name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) by constructing crafted zone data and then making a query for a name in that zone.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 30, 2017 | Jul 29, 2015 |
| Centos_linux | — | Upgrade bindUpgrade bind-sdbUpgrade bind-develUpgrade bind-licenseUpgrade bind-libsUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-libs-liteUpgrade bind-sdb-chrootUpgrade bind-lite-devel | Dec 1, 2016 | Jul 8, 2015 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jul 8, 2015 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Oct 27, 2015 | Jul 8, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 6, 2015 |
| Freebsd | — | Upgrade bind910-baseUpgrade FreeBSDUpgrade bind910Upgrade bind99-baseUpgrade bind99 | Dec 10, 2025 | Jul 7, 2015 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jul 8, 2015 |
| Hpux | — | Update NameService.BIND-RUN to the latest versionUpdate NameService.BIND-AUX to the latest version | Aug 11, 2017 | Jul 8, 2015 |
| Oracle_linux | — | Upgrade bind-chrootUpgrade bind-sdbUpgrade bind-utilsUpgrade bind-libs-liteUpgrade bind-lite-develUpgrade bind-develUpgrade bind-libsUpgrade bind-sdb-chrootUpgrade bind-licenseUpgrade bind | Oct 16, 2024 | Jul 8, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 7, 2015 |
| Suse | — | Upgrade bind-develUpgrade bind-chrootenvUpgrade bind-libs-32bitUpgrade liblwres160Upgrade libisccc160Upgrade bind-libs-x86Upgrade libns1604Upgrade python3-bindUpgrade python-bindUpgrade libirs1601Upgrade libisccc1600Upgrade libbind9-160Upgrade libisc166-32bitUpgrade libisccfg160Upgrade libirs-develUpgrade libisc1606Upgrade bind-docUpgrade libdns1605Upgrade libisccfg1600Upgrade libirs160Upgrade bind-devel-32bitUpgrade bind-utilsUpgrade libbind9-1600Upgrade libdns169Upgrade bind-libsUpgrade bindUpgrade libisc166 | Dec 18, 2015 | Jul 8, 2015 |
| Ubuntu | — | Upgrade bind9 | Nov 8, 2024 | Jul 8, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub